Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2706▼ 533 respecto a la semana anterior
Críticas / altas1274▼ 219 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 249 respecto a la semana anterior
288 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.57% | — | Health Care Hospital Management System Project Health Care Hospital Management System | 18/6/2024 | 17/6/2026 | CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Room Information module via the id parameter. | |
| Modificada | Media (5.4) | 0.33% | — | Health Care Hospital Management System Project Health Care Hospital Management System | 18/6/2024 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname and lname parameters under the Staff Info page. | |
| Modificada | Alta (8.8) | 0.62% | — | Health Care Hospital Management System Project Health Care Hospital Management System | 18/6/2024 | 17/6/2026 | CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Patient Info module via the searvalu parameter. | |
| Analizada | Media (6.9) | 0.74% | — | Warrendaloyan Online Hospital Management System | 26/5/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Hospital Management System 1.0. Affected is an unknown function of the file departmentDoctor.php. The manipulation of the argument deptid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Analizada | Alta (7.6) | 0.53% | — | Mayurik Hospital Management System | 29/4/2024 | 17/6/2026 | Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user parameters for unauthorized access and modifications via crafted POST request to /patient/edit-user.php. | |
| Analizada | Alta (8.8) | 0.55% | — | Phpgurukul Hospital Management System | 7/3/2024 | 17/6/2026 | Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php. | |
| Analizada | Baja (2.7) | 0.44% | — | Phpgurukul Hospital Management System | 7/3/2024 | 17/6/2026 | Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the doc_number parameter at his_admin_view_single_employee.php. | |
| Analizada | Alta (8.1) | 0.50% | — | Phpgurukul Hospital Management System | 7/3/2024 | 17/6/2026 | Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_view_single_patien.php. | |
| Modificada | Alta (7.5) | 0.69% | 💥 PoC | Modernasistemas Modernanet Hospital Management System 2024 | 29/1/2024 | 17/6/2026 | The Moderna Sistemas ModernaNet Hospital Management System 2024 is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. This vulnerability resides in the system's handling of user data access through a /Modernanet/LAUDO/LAU0000100/Laudo?id= URI. By manipulating this id parameter, an attacker can… | |
| Modificada | Media (4.9) | 0.71% | — | Phpgurukul Hospital Management System | 10/1/2024 | 17/6/2026 | A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an admin. | |
| Modificada | Crítica (9.8) | 1.2% | — | Phpgurukul Hospital Management System | 10/1/2024 | 17/6/2026 | A JQuery Unrestricted Arbitrary File Upload vulnerability was discovered in Hospital Management System V4.0 which allows an unauthenticated attacker to upload any file to the server. | |
| Modificada | Media (6.1) | 0.50% | — | Phpgurukul Hospital Management System | 10/1/2024 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability was discovered in Hospital Management System V4.0 which allows an attacker to execute arbitrary web scripts or HTML code via a malicious payload appended to a username on the 'Edit Profile" page and triggered by another user visiting the profile. | |
| Modificada | Media (4.9) | 0.71% | — | Phpgurukul Hospital Management System | 10/1/2024 | 17/6/2026 | A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under the 'Contact Us Queries -> Unread Query' tab. | |
| Modificada | Crítica (9.8) | 0.53% | — | Phpgurukul Hospital Management System | 10/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file admin/query-details.php. The manipulation of the argument adminremark leads to sql injection. The exploit has been disclosed to the public and may be used. The associated… | |
| Modificada | Crítica (9.8) | 0.65% | — | Phpgurukul Hospital Management System | 10/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file admin/patient-search.php. The manipulation of the argument searchdata leads to sql injection. The exploit has been disclosed to the public and… | |
| Modificada | Crítica (9.8) | 0.65% | — | Phpgurukul Hospital Management System | 10/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in PHPGurukul Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file admin/change-password.php. The manipulation of the argument cpass leads to sql injection. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Crítica (9.8) | 0.70% | — | Phpgurukul Hospital Management System | 10/1/2024 | 17/6/2026 | A vulnerability classified as critical has been found in PHPGurukul Hospital Management System 1.0. Affected is an unknown function of the file admin/contact.php. The manipulation of the argument mobnum leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this… | |
| Modificada | Crítica (9.8) | 0.70% | — | Phpgurukul Hospital Management System | 10/1/2024 | 17/6/2026 | A vulnerability was found in PHPGurukul Hospital Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/edit-doctor-specialization.php. The manipulation of the argument doctorspecilization leads to sql injection. The exploit has been disclosed to the public… | |
| Modificada | Media (6.1) | 0.88% | — | Phpgurukul Hospital Management System | 7/1/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file index.php#contact_us of the component Contact Form. The manipulation of the argument Name/Email/Message leads to cross site scripting. It is possible to initiate the… | |
| Modificada | Crítica (9.8) | 0.94% | — | Surajghosh Hospital Management System | 7/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Kashipara Hospital Management System up to 1.0. Affected by this issue is some unknown functionality of the file registration.php. The manipulation of the argument name/email/pass/gender/age/city leads to sql injection. The attack may be launched… | |
| Modificada | Crítica (9.8) | 0.69% | — | Surajghosh Hospital Management System | 7/1/2024 | 17/6/2026 | A vulnerability classified as critical was found in Kashipara Hospital Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file login.php of the component Parameter Handler. The manipulation of the argument email/password leads to sql injection. The attack can be launched… | |
| Modificada | Media (5.4) | 1.5% | 💥 PoC | Phpgurukul Hospital Management System | 30/12/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in PHPGurukul Hospital Management System 1.0. This affects an unknown part of the file registration.php. The manipulation of the argument First Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Alta (7.2) | 1.5% | 💥 PoC | Phpgurukul Hospital Management System | 30/12/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the component Admin Dashboard. The manipulation leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 0.66% | — | Free Hospital Management System FOR Small Practices Project Free Hospital Management System FOR Small Practices | 15/10/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /vm/admin/doctors.php of the component Parameter Handler. The manipulation of the argument search leads to sql injection. The… | |
| Modificada | Crítica (9.1) | 0.81% | — | Hospital Management System Project Hospital Management System | 29/9/2023 | 17/6/2026 | Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php. |